\r\n\r\n
\r\n
i
\r\n
\r\n Quick Answer\r\n

The AIGP BoK v2.1 has four domains: Domain I (AI Foundations, ~18%), Domain II (Laws & Frameworks, ~27%), Domain III (Responsible AI, ~30%), and Domain IV (GRC, ~25%). Most candidates over-invest in Domains I and II because the content feels familiar — and under-invest in Domain III, which is the most common failure domain for privacy and legal backgrounds.

\r\n
\r\n
\r\n\r\n

How you allocate study time across the four AIGP domains is one of the highest-leverage decisions in your preparation. The domains are not equally weighted, they are not equally difficult across all backgrounds, and the version-2.1 update added specific new content to Domain II and III that candidates using older materials will miss entirely. This guide maps the weighting, the background-specific risk areas, and a practical 8-week allocation.

\r\n\r\n
\r\n
\r\n
\r\n
Domain I
\r\n

Foundations of AI and Data

\r\n
\r\n
~18%
\r\n
\r\n
\r\n Standard Risk for Most Backgrounds\r\n

Covers AI system types, the AI development lifecycle from data collection through deployment and monitoring, machine learning fundamentals at a governance-relevant level, and data governance principles. The v2.1 update shifted emphasis from individual model risk to system risk — the interactions between components, deployment infrastructure, and human workflows.

\r\n

What trips candidates: Technical candidates tend to underestimate this domain because the content feels basic — but the exam tests governance application, not technical depth. Privacy candidates often have gaps in AI system lifecycle stages that are distinct from data processing lifecycles.

\r\n

Key v2.1 additions: Agentic AI risk is explicitly addressed here. Multi-agent system governance, autonomous decision-making accountability, and the new Provider role distinction are all testable content added in February 2026.

\r\n
    \r\n
  • AI system vs. AI model distinction (newly emphasised in v2.1)
  • \r\n
  • Agentic AI and multi-agent system governance
  • \r\n
  • Data lifecycle and provenance in governance contexts
  • \r\n
  • Deployment infrastructure risk (cloud, APIs, edge)
  • \r\n
\r\n
\r\n
\r\n\r\n
\r\n
\r\n
\r\n
Domain II
\r\n

Laws, Standards, and Frameworks

\r\n
\r\n
~27%
\r\n
\r\n
\r\n Moderate Risk — Content-Heavy, v2.1 Updated\r\n

Covers the EU AI Act (by far the most heavily tested regulation), GDPR’s AI-relevant provisions, NIST AI RMF, ISO 42001, ISO 42005 (newly added in v2.1), and a curated set of national frameworks (South Korea AI Basic Act, Colorado SB 205, Texas TRAIGA). Also covers the OECD AI Principles and UNESCO Recommendation on AI Ethics as foundational documents. what ISO 42001 actually requires.

\r\n

What trips candidates: Treating the EU AI Act as a legal recall exercise — memorising article numbers and definitions — rather than building operational translation fluency. The exam tests which obligations apply to which role at which lifecycle stage, not whether you can recite Article 9 verbatim.

\r\n

Key v2.1 additions: ISO 42005 is now explicitly tested alongside ISO 42001. South Korea’s AI Basic Act, Colorado SB 205, and Texas TRAIGA are added to the global law coverage. The EU AI Act Provider/Deployer distinction is now a primary focus.

\r\n
    \r\n
  • EU AI Act: risk tiers, Provider vs. Deployer obligations, conformity assessment, prohibited uses
  • \r\n
  • ISO 42001 (management system) vs. ISO 42005 (impact assessment) — distinguish clearly
  • \r\n
  • NIST AI RMF: Govern, Map, Measure, Manage functions and their exam application
  • \r\n
  • GDPR Articles 22 and 35 intersections with EU AI Act requirements
  • \r\n
\r\n
\r\n
\r\n\r\n
\r\n
\r\n
\r\n
Domain III
\r\n

Responsible AI Practices

\r\n
\r\n
~30%
\r\n
\r\n
\r\n Highest Risk — Most Under-Studied by Privacy & Legal Backgrounds\r\n

The heaviest domain by weight and the most consistently under-prepared for by candidates from privacy or legal backgrounds. Covers algorithmic accountability, bias identification and mitigation, explainability and interpretability, safety testing methodologies (including red teaming), human oversight mechanisms, environmental impact of AI systems, and the responsible AI lifecycle.

\r\n

What trips candidates: This domain requires familiarity with how AI systems behave, not just how they are regulated. Candidates who cannot interpret a bias evaluation result, explain the difference between fairness metrics (demographic parity vs. equal opportunity), or describe what a model card documents will struggle with scenario questions in this domain regardless of how much regulatory content they know.

\r\n

Key v2.1 additions: Agentic AI safety and oversight requirements strengthened. Red teaming and adversarial testing now appear more prominently. C2PA and content provenance standards added to the transparency and watermarking content area.

\r\n
    \r\n
  • Bias types: historical, representation, measurement, aggregation — and their mitigations
  • \r\n
  • Explainability: LIME, SHAP at a conceptual governance level (not mathematical implementation)
  • \r\n
  • Safety testing: red teaming scope, adversarial inputs, supply chain risk
  • \r\n
  • Human oversight: meaningful vs. performative oversight distinction
  • \r\n
  • Model cards, datasheets for datasets, and transparency documentation
  • \r\n
\r\n
\r\n
\r\n\r\n
\r\n
\r\n
\r\n
Domain IV
\r\n

Governance, Risk and Compliance

\r\n
\r\n
~25%
\r\n
\r\n
\r\n Standard Risk — Familiar for GRC Professionals\r\n

Covers enterprise AI governance programme design, risk management frameworks applied to AI contexts, audit and assurance for AI systems, third-party and vendor risk management, and the accountability structures that connect AI governance to broader enterprise GRC. Most scenario questions in this domain involve selecting the right governance control for a described risk context.

\r\n

What trips candidates: Applying GRC frameworks — particularly NIST AI RMF functions — to AI-specific scenarios. Candidates familiar with general enterprise risk frameworks sometimes struggle with AI-specific variants of risk concepts (model drift, algorithmic accountability, AI supply chain risk) that require context-specific responses.

\r\n
    \r\n
  • AI governance programme structure: policies, roles, escalation paths, board reporting
  • \r\n
  • Third-party AI vendor risk: due diligence, contract clauses, ongoing monitoring
  • \r\n
  • AI audit: what auditors look for, documentation requirements, evidence standards
  • \r\n
  • Incident response for AI-specific failures: hallucination, drift, bias amplification
  • \r\n
\r\n
\r\n
\r\n\r\n

Study Allocation by Background

\r\n\r\n
\r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n
BackgroundDomain IDomain IIDomain IIIDomain IVTotal Hours
Privacy professional (holds CIPP)10%25%40%25%40–60 hrs
Legal professional15%20%40%25%60–80 hrs
Compliance / GRC professional15%25%35%25%60–80 hrs
Technical / data science background5%40%30%25%60–90 hrs
No privacy or AI background20%25%30%25%90–120 hrs
\r\n
\r\n\r\n

8-Week Study Plan

\r\n\r\n
\r\n
\r\n
Week 1
\r\n
Orientation: Read the full BoK v2.1 document. Map your background against the domain risk table above. Identify which domain is your highest-risk gap and mark it as the domain that will receive extra sessions in weeks 4–6.
\r\n
\r\n
\r\n
Week 2
\r\n
Domain I: AI system lifecycle, types, deployment contexts. Focus specifically on the agentic AI and multi-agent system content added in v2.1. Technical backgrounds can compress this to 3–4 hours.
\r\n
\r\n
\r\n
Week 3
\r\n
Domain II (regulatory): EU AI Act risk tiers, Provider vs. Deployer obligations, prohibited uses, conformity assessment. GDPR Articles 22 and 35 intersections. Do not attempt to memorise article numbers — build the operational mapping instead.
\r\n
\r\n
\r\n
Week 4
\r\n
Domain II (frameworks): NIST AI RMF (Govern, Map, Measure, Manage). ISO 42001 vs. ISO 42005 distinction. OECD AI Principles. New global law additions: South Korea, Colorado, Texas. This is also a good week for first scenario question practice.
\r\n
\r\n
\r\n
Week 5
\r\n
Domain III (part 1): Bias types, fairness metrics, mitigation strategies. Explainability at a governance level. Model cards and transparency documentation. This is the domain most candidates need most time on — do not rush it.
\r\n
\r\n
\r\n
Week 6
\r\n
Domain III (part 2): Safety testing, red teaming scope, adversarial inputs. Human oversight mechanisms. Agentic AI safety requirements from v2.1. C2PA and content provenance. Run practice questions focused exclusively on Domain III scenarios.
\r\n
\r\n
\r\n
Week 7
\r\n
Domain IV: AI governance programme design, vendor risk management, audit readiness, incident response for AI-specific failures. Practise applying NIST AI RMF functions to scenario questions.
\r\n
\r\n
\r\n
Week 8
\r\n
Integration & practice: Full scenario-based practice sessions only — no more content reading. Time yourself at 1 min 39 sec per question. Identify any remaining domain gaps and target them in the final 2–3 days. Review exam-day logistics.
\r\n
\r\n
\r\n\r\n
\r\n The Scenario Triage Model\r\n

For every practice question, apply the same three-step filter before looking at answer choices: (1) What Role does the scenario describe? (2) Which Framework or regulation applies? (3) What Lifecycle stage is the AI system at? This Role × Framework × Lifecycle model is the single most effective antidote to the exam’s plausible-distractor answer choices. See why memorising the EU AI Act won’t pass the AIGP exam for the full triage breakdown.

\r\n
\r\n\r\n
\r\n
Bottom Line
\r\n

Domain III is the highest-weight domain and the most consistently under-prepared for by the backgrounds that most commonly attempt the AIGP. If you have a privacy or legal background, allocate 35–40% of your study time to Domain III regardless of how comfortable the regulatory content in Domain II feels. The candidates who pass on the first attempt have almost always done this; the candidates who fail on their first attempt and are surprised by the result almost always haven’t.

\r\n

Related reading: AIGP BoK v2.1 changes, how many hours to study by background, and 10 practice questions calibrated to the 2026 exam.

\r\n